brand-guidelines
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions are intended to be applied to "any sort of artifact", which creates an ingestion surface for indirect prompt injection.\n
- Ingestion points: SKILL.md describes applying styles to "any sort of artifact that may benefit from having Ferment's look-and-feel".\n
- Boundary markers: No delimiters or instructions to ignore embedded instructions within processed artifacts are present.\n
- Capability inventory: No scripts, subprocess calls, or tool invocations are defined in the skill files.\n
- Sanitization: No sanitization or filtering of external content is specified.\n- [EXTERNAL_DOWNLOADS]: The skill references a typography resource from Google Fonts, a well-known service.\n
- Evidence:
https://fonts.googleapis.com/css2?family=Poppins:wght@300;400;600;700in SKILL.md.\n- [NO_CODE]: No scripts or executable code were found; the skill consists entirely of markdown documentation and a license.
Audit Metadata